PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an improper access control vulnerability in the DirectIo64.sys kernel driver that allows unprivileged local users to perform privileged hardware operations by opening a handle to the device object created without a security descriptor. Attackers can issue IOCTLs through the permissive default Windows ACL applied to the device to access restricted hardware operations regardless of privilege or integrity level.
Metrics
Affected Vendors & Products
References
History
Mon, 07 Sep 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Passmark
Passmark burnintest Passmark osforensics Passmark performancetest |
|
| Vendors & Products |
Passmark
Passmark burnintest Passmark osforensics Passmark performancetest |
Fri, 04 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 04 Sep 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an improper access control vulnerability in the DirectIo64.sys kernel driver that allows unprivileged local users to perform privileged hardware operations by opening a handle to the device object created without a security descriptor. Attackers can issue IOCTLs through the permissive default Windows ACL applied to the device to access restricted hardware operations regardless of privilege or integrity level. | |
| Title | PassMark PerformanceTest, BurnInTest, and OSForensics Improper Access Control via DirectIo64.sys | |
| Weaknesses | CWE-732 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-09-04T18:33:01.380Z
Updated: 2026-09-04T18:54:39.896Z
Reserved: 2026-08-25T19:56:44.777Z
Link: CVE-2026-80112
Updated: 2026-09-04T18:54:33.927Z
Status : Awaiting Analysis
Published: 2026-09-04T19:17:27.823
Modified: 2026-09-08T20:10:30.270
Link: CVE-2026-80112
No data.